Malicious PDF — malware analysis report

Static analysis result for SHA-256 07bad0c2e1017961…

MALICIOUS

PDF

90.3 KB Created: 2021-02-14 16:45:16 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 214c03e950bff33881b6be9a91ea260d SHA-1: 23c666f0425653870bb898046cfe1790989bfef1 SHA-256: 07bad0c2e1017961321384cc41f7bb0d970677cb993bc1a04d2ee6db924599d0
156 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains numerous external links, many of which are part of a link farm designed to artificially inflate search engine rankings or redirect users to malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded URLs suggest an attempt to exploit users through deceptive content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 5

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://jottigo.ru/wb?keyword=amazon%20echo%20alexa%20information PDF link annotation
    • https://cdn.sqhk.co/duwokarewesu/ia3TEe1/optical_illusion_drawing_with_color.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4489838/normal_600249ef48e97.pdfIn PDF document text
    • https://cdn.sqhk.co/devisofage/jhf2mge/turn_off_mail_notification_sound_windows_10.pdfIn PDF document text
    • https://lofidebonejiniz.weebly.com/uploads/1/3/5/3/135334880/6765054.pdfIn PDF document text
    • https://cdn.sqhk.co/jumupebuvi/gjelDWR/nubusenos.pdfIn PDF document text
    • https://cdn.sqhk.co/fiporalisu/ijwhbhi/my_piano_app.pdfIn PDF document text
    • https://cdn.sqhk.co/wezopexa/gejahbk/igcse_chemistry_electrolysis_questions_and_answers.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4393022/normal_5fcc53b7403e0.pdfIn PDF document text
    • https://fevuxutub.weebly.com/uploads/1/3/4/1/134131759/2908b7b5244.pdfIn PDF document text
    • https://cdn.sqhk.co/laripikiwafo/Cghjcjh/bitazavofafivajap.pdfIn PDF document text
    • https://nogudoge.weebly.com/uploads/1/3/4/0/134017621/5797666.pdfIn PDF document text
    • https://cdn.sqhk.co/ludafojebi/gVviehg/72652520103.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/fodose/75483569429.pdfIn PDF document text
    • https://s3.amazonaws.com/lakujusitejojet/delicious_emily_honeymoon_cruise_full_apk.pdfIn PDF document text
    • https://s3.amazonaws.com/dikobepibelun/bomb_game_ppt_template.pdfIn PDF document text
    • https://s3.amazonaws.com/falevi/greenhouse_gas_emissions_by_country_2017.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0001307d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1307D 23908 bytes
SHA-256: 22206893abb1c6098a731b288bc99694cce75dcaad5b0d3741d50f978de9238f
font_00_sfnt_off0000eecc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xEECC 3012 bytes
SHA-256: 4c82ed216c71b3195c62b59d7d043c80317966addc7fa5a70e264b1a80708143
font_01_sfnt_off0000f993.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF993 5048 bytes
SHA-256: dd82307b179eeaf300fc72c5d74d142e1b6437b148f6efca021a7bc80f22729c
font_02_sfnt_off00010aa2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10AA2 10976 bytes
SHA-256: 9888c638c9793e55b15639b21c53a8d21a26f73751be6a2aca80502cef67ccfe